In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting since there is no validation on the input being sent to the name
parameter in noticeWizard
endpoint. Due to this flaw an authenticated attacker could inject arbitrary script and trick other admin users into downloading malicious files.
{ "vanir_signatures": [ { "deprecated": false, "signature_type": "Function", "target": { "file": "opennms-webapp/src/main/java/org/opennms/web/controller/admin/group/GroupController.java", "function": "renameGroup" }, "id": "CVE-2021-25929-04412c6e", "digest": { "length": 314.0, "function_hash": "144759024573714915384785318319942410353" }, "signature_version": "v1", "source": "https://github.com/opennms/opennms/commit/eb08b5ed4c5548f3e941a1f0d0363ae4439fa98c" }, { "deprecated": false, "signature_type": "Function", "target": { "file": "opennms-webapp/src/main/java/org/opennms/web/admin/users/RenameUserServlet.java", "function": "doPost" }, "id": "CVE-2021-25929-26db798a", "digest": { "length": 378.0, "function_hash": "140896969588649620875571293911303623336" }, "signature_version": "v1", "source": "https://github.com/opennms/opennms/commit/eb08b5ed4c5548f3e941a1f0d0363ae4439fa98c" }, { "deprecated": false, "signature_type": "Line", "target": { "file": "opennms-webapp/src/main/java/org/opennms/web/admin/users/AddNewUserServlet.java" }, "id": "CVE-2021-25929-756876d8", "digest": { "line_hashes": [ "63862115445021482406981461159020448473", "192790766046859987790732110517539223001", "264559957673844931483714759827957494060", "187562419973017837990659765287661653505" ], "threshold": 0.9 }, "signature_version": "v1", "source": "https://github.com/opennms/opennms/commit/eb08b5ed4c5548f3e941a1f0d0363ae4439fa98c" }, { "deprecated": false, "signature_type": "Line", "target": { "file": "opennms-webapp/src/main/java/org/opennms/web/admin/users/RenameUserServlet.java" }, "id": "CVE-2021-25929-84167b85", "digest": { "line_hashes": [ "89256397304596016052036103843694799455", "228142828937052465100599374335507169788", "253436531422684568205797174898232887867" ], "threshold": 0.9 }, "signature_version": "v1", "source": "https://github.com/opennms/opennms/commit/eb08b5ed4c5548f3e941a1f0d0363ae4439fa98c" }, { "deprecated": false, "signature_type": "Line", "target": { "file": "opennms-webapp/src/main/java/org/opennms/web/controller/admin/group/GroupController.java" }, "id": "CVE-2021-25929-b51ae946", "digest": { "line_hashes": [ "58730506138354010431660930680209411599", "131372045428180590852460578241088976601", "107737349864204963929678012583384325367", "6897653343869269317735066625920671701", "220882383980174487142093456676728608479", "52485355072899409265839311709820086238" ], "threshold": 0.9 }, "signature_version": "v1", "source": "https://github.com/opennms/opennms/commit/eb08b5ed4c5548f3e941a1f0d0363ae4439fa98c" }, { "deprecated": false, "signature_type": "Function", "target": { "file": "opennms-webapp/src/main/java/org/opennms/web/controller/admin/group/GroupController.java", "function": "addGroup" }, "id": "CVE-2021-25929-cb44f906", "digest": { "length": 610.0, "function_hash": "296653347434168606010481034581794117613" }, "signature_version": "v1", "source": "https://github.com/opennms/opennms/commit/eb08b5ed4c5548f3e941a1f0d0363ae4439fa98c" }, { "deprecated": false, "signature_type": "Line", "target": { "file": "smoke-test/src/test/java/org/opennms/smoketest/UserIT.java" }, "id": "CVE-2021-25929-d4ce405d", "digest": { "line_hashes": [ "215985755002245887884707550113681684850", "11438173654715828717935667960271049116", "176681594848500904939248140376016076557" ], "threshold": 0.9 }, "signature_version": "v1", "source": "https://github.com/opennms/opennms/commit/eb08b5ed4c5548f3e941a1f0d0363ae4439fa98c" }, { "deprecated": false, "signature_type": "Function", "target": { "file": "opennms-webapp/src/main/java/org/opennms/web/admin/users/AddNewUserServlet.java", "function": "doPost" }, "id": "CVE-2021-25929-eed35066", "digest": { "length": 1151.0, "function_hash": "198479055700301882740520908056306576753" }, "signature_version": "v1", "source": "https://github.com/opennms/opennms/commit/eb08b5ed4c5548f3e941a1f0d0363ae4439fa98c" } ] }